Job description
We’re looking for a Cyber Threat Intelligence (CTI) Research Intern to help us track, analyze, and report on emerging cyber threats — with a strong focus on dark web and open-source intelligence (OSINT). You’ll use OSINT tooling, scripts, and automation to discover leaked data, identify threat actors, track stealer logs, and support our overall Threat Intelligence strategy.
Key Responsibilities
Dark Web & Deep Web Research Monitor dark web forums, marketplaces, Telegram channels, paste sites, and other underground sources for potential leaks related to our customers (credentials, PII, configs, access offers, etc.) Identify and track threat actors, their aliases, activity patterns, and infrastructure. OSINT-led Threat Hunting Use OSINT tools and frameworks (e.
g., Maltego, Spider. Foot, Shodan, Censys, whois, etc.) to gather intelligence on domains, IPs, email addresses, and infrastructure related to threats. Correlate data from multiple sources (dark web, social media, news, public feeds) into meaningful intelligence. Python Scripting & Automation Build and maintain Python scripts to automate data collection from open sources and dark web mirrors/APIs.
Clean, normalize, and enrich collected data (e.g., parsing stealer logs, extracting indicators of compromise, tagging entities). Threat Intel Strategy & Reporting Contribute to the design and improvement of our Threat Intelligence strategy, including data sources, workflows, and prioritization. Create concise intelligence reports, dashboards, and alerts for internal teams and customers (what happened, who is behind it, impact, recommended actions).
Maintain structured repositories of Indicators of Compromise (IOCs), TTPs, and threat actor profiles. Support for Security Operations & Product Work with SOC / Incident Response teams to provide context for ongoing alerts and investigations. Map collected intelligence to frameworks like MITRE ATT&CK to understand and explain attacker behavior.
Research & Knowledge Sharing Track emerging threat trends, new ransomware groups, exploit kits, and data leak forums. Document processes, tools, and findings so they can be reused by the wider team.
Requirements
Strong interest in cybersecurity, threat intelligence, and attacker behavior. Good understanding of: OSINT concepts and tools. Dark web vs deep web, Tor, and common underground ecosystems. Hands-on experience with Python for: Writing small scripts for data collection and parsing (web scraping, API calls, regex, etc.) Basic data handling (JSON, CSV, simple data analysis).
Familiarity with: Basic networking concepts (IP, DNS, ports, HTTP/S). Common attack types (phishing, credential stuffing, ransomware, data breaches). Ability to read & interpret breach data (usernames, passwords, hashes, stealer logs) with a strong sense of confidentiality and ethics. Strong written communication skills to convert technical findings into clear summaries.
Benefits
Real-world exposure to dark web intelligence, stealer logs, and breach data workflows. Experience in building repeatable threat intel processes and automations. Mentorship from security engineers / analysts and a chance to influence how our Threat Intel function evolves. You don’t need to know everything on day one, but you should be curious, comfortable experimenting with tools and scripts, and serious about responsible handling of sensitive data.